cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
536
Views
4
Helpful
3
Replies

convert production cisco router into IOS based firewall

Hiral Tewar
Level 1
Level 1

Hi,

I am planning to convert our production router into IOS based firewall.

  • Please advice about DOs & DON'Ts.
  • What will happen to running configuration of Router?
    • Will it be still valid?

Thank you for your time and guidence !

 

1 Accepted Solution

Accepted Solutions

Andre Neethling
Level 4
Level 4

Nothing will happen to your normal routing configs. Memory and CPU utilization may increase as you add services.

Will your router be attached directly to the internet, or behind another device?

Will you be using IOS Zone Based Firewall? If so, remember the "self" zone (the router itself). By default everything is allowed to and from the "self" zone. I would recommend a self zone policy from the start.

View solution in original post

3 Replies 3

Andre Neethling
Level 4
Level 4

Nothing will happen to your normal routing configs. Memory and CPU utilization may increase as you add services.

Will your router be attached directly to the internet, or behind another device?

Will you be using IOS Zone Based Firewall? If so, remember the "self" zone (the router itself). By default everything is allowed to and from the "self" zone. I would recommend a self zone policy from the start.

Thank you for your reply.

 

Router is attached directly to internet. I am thinking of using Zone based fw. Thank you for headsup on self zone.

During my brief research, i come acorss many blogs which suggest to use router for routing only. Whats your openion?

I am using my router directly attached to the internet for Routing, IPSEC RA VPN, SSL RA VPN, Zone Based Firewall. It's important when enabling these extra features on the router, to make sure that your router has enough Memory and CPU. If you are using this for a production environment, make sure you know what you current performance and hardware resource utilization is. If you add too many features, your user experience could be affected.

I only have a few devices in my home office network, and I am using a 1841 router with additional memory (128MB+128MB). My CPU and Memory never go above 40%. What router do you have? How many Clients do you have? These are questions you must ask yourself. Do some baseline assessments on the CPU/Memory/Internet performance.

Review Cisco Networking for a $25 gift card